Job Description: SAP S/4HANA Security Architect
Location: Remote
Duration: Long-Term Contract
Must have: SAP Security Architecture, Brownfield Migration, SAP Security Weaver/Path lock and Fiori Security.
Position Overview:
moving from SAP ECC to SAP S/4HANA 2025 Edition. We are seeking a senior SAP S/4HANA Security Architect to lead the security workstream for our brownfield migration. This person will own security impact analysis, role redesign, Fiori and HANA security implementation, and SoD/risk management using Security Weaver (Pathlock) as the primary governance tool. Experience with SAP GRC Access Control is also acceptable where Security Weaver exposure is limited.
Core Requirements (Non-Negotiable):
- Minimum 2-3 full lifecycle ECC S/4HANA brownfield migration projects (hands-on conversion experience).
- Direct, hands-on execution of SU25 (Phases 1-4) and role retrofit activities during conversion.
- Fiori security implementation experience: catalogs, groups, business roles, OData activation, SICF.
- Enterprise role redesign and remediation at scale (analysis and remediation of 1,000+ roles preferred).
- SAP Readiness Check and Simplification Item Catalog impact analysis experience.
- Hands-on experience with Security Weaver (Pathlock) OR SAP GRC Access Control for SoD analysis, simulation, remediation, and reporting.
- Strong understanding of SoD rule design and risk mitigation strategy during ECC S/4 transitions.
Key Responsibilities:
- Lead SAP security strategy and execution for ECC S/4HANA transformation (brownfield conversion).
- Perform role impact analysis, cleanup, and remediation; execute SU25 conversion steps and validate role behavior in S/4.
- Design and implement a Fiori-first security model (catalogs, groups, business roles) and secure OData/SICF services.
- Configure and manage Security Weaver (Pathlock) controls; alternatively align SAP GRC rule sets where applicable.
- Migrate SoD rule sets and control frameworks from ECC to S/4 define interim compensating controls.
- Conduct workshops with functional teams (FI/CO/MM/SD/EWM), Basis, Development, and Audit to validate security models.
- Support cutover, security testing, and post-go-live authorization validation and stabilization.
Preferred Qualifications:
- 15+ years of SAP Security experience (ECC and S/4HANA).
- Proven track record in 2+ ECC S/4HANA brownfield conversions.
- Experience with Security Weaver (Pathlock) strongly preferred.
- SAP GRC Access Control experience in complex enterprise environments.
- Experience working in SOX/ITGC-regulated environments and preparing audit evidence.
- Strong communication skills and ability to lead cross-functional workshops.